In mid-June 2021, Motherboard reported how attackers bought stolen Slack authentication cookies for about $10, walked into an Electronic Arts workspace as an employee, and then talked IT support into handing over multifactor authentication tokens with a lost-phone story. That helpdesk step, not the cookie shop, is what opened EA’s corporate network. Roughly 780 GB of game source code and tools were claimed stolen; EA said no player data was accessed.

Public reporting does not establish who stole the original Slack cookies, which employee account was hit, or exact intrusion calendar dates. The path that matters for workforce MFA is clear: chat-only identity proofing re-issued a usable factor after a lost-phone claim, twice.

If you want the prevention angle on enrollment and recovery controls that stop helpdesk lost-phone token handoffs, read the related article on mfa2point0.com.

FAQ

How did the Electronic Arts attackers get corporate network access?

The Electronic Arts attackers reached the corporate network after EA IT support provided multifactor authentication tokens over Slack. According to a representative for the hackers speaking to Motherboard, once inside Slack they messaged IT support, claimed a phone was lost at a party, and requested an MFA token. They said that request succeeded twice. Purchased Slack session cookies only got them into chat as the victim employee; the helpdesk handoff is what unlocked network access used later for source-code theft.

Did legacy MFA fail at the Slack login in the EA breach?

No. Public reporting on the Electronic Arts breach does not describe a failed Slack password or MFA challenge at login. Attackers purchased already-valid Slack authentication cookies online for about $10 and replayed them. Those cookies are post-authentication session material. Password or MFA prompts at Slack had already been satisfied for the legitimate employee session before the cookies were stolen and sold. Stronger login MFA does not invalidate cookies already issued and sitting in a marketplace.

What exactly did EA IT hand over, and why did that matter?

EA IT support provided multifactor authentication tokens after a lost-phone story delivered over Slack chat. Attackers used those tokens to gain access to EA’s corporate network. From there, according to the Motherboard account, they used a developer game-compilation service, created a VM, reached further internal services, and downloaded source code and tools. EA confirmed an intrusion where a limited amount of game source code and related tools were stolen and stated no player data was accessed. Chat-only recovery without binding to an already-enrolled employee device is the failure mode.

How much was stolen from Electronic Arts, and was player data involved?

Hackers claimed about 780 GB of data, including FIFA 21 source and matchmaking tools, Frostbite engine source, internal dev tools, and sample documents on PlayStation VR, FIFA digital crowds, and game AI. EA’s statement, via Motherboard, said: "We are investigating a recent incident of intrusion into our network where a limited amount of game source code and related tools were stolen. No player data was accessed, and we have no reason to believe there is any risk to player privacy." Public reporting does not establish a ransom demand.

Would fixing MFA at login have stopped the whole EA incident?

Fixing only the Slack login ceremony would not have stopped cookie replay of an already-issued session, and it would not have blocked source-code download after network access already existed. The phase where workforce MFA design actually bites is the helpdesk lost-phone path: re-issuing a transferable MFA token after chat-only proofing. A fix exists that hardens enrollment and recovery so that path cannot hand an attacker a usable factor. Cookie theft after a legitimate login and post-access file theft remain separate, harder problems. Public reporting does not name a threat actor group for this incident.